Why integrate
Management systems built on the ISO harmonized structure share the same clauses for context, leadership, planning, support, operation, evaluation, and improvement. Auditing them separately means covering the same ground twice with different auditors on different dates. An integrated audit examines the shared clauses once and then addresses the requirements specific to each standard.
ISO/IEC 27701: privacy information management
ISO/IEC 27701 adds requirements and controls for organizations acting as personal data controllers, processors, or both. It provides a structured way to demonstrate privacy governance that maps to GDPR, UK GDPR, CCPA, and similar laws, without being tied to any one of them.
An integrated ISO 27001 and ISO 27701 audit covers:
- Extended ISMS requirements for privacy, including privacy-specific risk assessment
- Additional guidance on ISO 27001 Annex A controls for privacy
- Controller-specific controls: lawful basis, consent, data subject rights, transparency
- Processor-specific controls: customer instructions, sub-processor management, breach notification
- Privacy by design and data minimization in development and operations
ISO 22301: business continuity management
ISO 22301 sets requirements for a business continuity management system: understanding what must not stop, planning how to keep it running, and testing that the plans work. It sits naturally beside ISO 27001, which already requires ICT readiness for business continuity and incident response.
An integrated ISO 27001 and ISO 22301 audit covers:
- Business impact analysis and risk assessment for disruption
- Continuity strategies and solutions, and how they were selected
- Business continuity plans and procedures, including communication
- Exercise and test programs, and what they showed
- Links between security incident management and continuity response
How it works in practice
We build a single audit plan that lists which requirements of each standard are covered in each session. Interviews with leadership, HR, and IT operations cover all standards at once. The report is consolidated, with findings tagged to the standard and clause they relate to. Separate certificates are issued for each standard so you can share whichever one a customer asks for.